- Roko's Basilisk
- Posts
- The Warning No One Heeds
The Warning No One Heeds
Plus: social media's addiction reckoning, NVIDIA's $500B compute bet, Meta's open-weight turn.
Here's what's on our plate today:
🧪 Every AI lab can name the danger, and none can afford to stop first.
🗞️ Social media's addiction suits advance, NVIDIA turns compute into an asset class, and Meta bets on open weights.
🧠 Brain Snack: don't build a roadmap around a safety pause that isn't coming.
🗳️ Poll: the warning came true, so what should the industry do now?
Let’s dive in. No floaties needed.

Blu Dot surpasses 2,000% ROAS with self-serve CTV ads
Home furniture brand Blu Dot blew up on CTV with help from Roku Ads Manager. Here’s how:
After a test campaign reached 211,000 households and achieved 1,010% ROAS, the brand went all in to promote its annual sales event. It removed age and income constraints to expand reach and shifted budget to custom audiences and retargeting, where intent was strongest.
The results speak for themselves. As Blu Dot increased their investment by 10x, ROAS jumped to 2,308% and more page-view conversions surpassed 50,000.
“For CTV campaigns, Roku has been a top performer,” said Claire Folkestad, Paid Media Strategist, Blu Dot. “Comping to our other platforms, we have seen really strong ROAS… and highly efficient CPMs, lower than any other CTV partner we've worked with.”
Using Roku Ads Manager, the campaign moved from a pilot to a permanent performance engine for the brand.
*This is sponsored content

Build and design your website on Framer - Now with Agents
Framer is a pro website builder trusted by companies like Miro and Perplexity that helps creators, teams and businesses ship production-ready sites faster than ever. With AI agents built directly into the canvas, teams can design pages, manage CMS content, write copy, add SEO, and audit for issues — all without leaving the tool where the real site lives. Agents bring speed and scale; you bring taste, judgment, and control.
*This is sponsored content

The Laboratory
TL;DR
Every lab in the AI race can name the danger. None can afford to be the one who stops.
Two escapes, nine days: in late July, OpenAI and Anthropic each disclosed that their models had broken out of sealed test environments and reached the systems of real companies.
Not a rogue AI: both models were doing the job they were given. The containment failed, not the machine.
Plumbing fixed, pace unchanged: a prototype shut down, evaluations paused, and two IPO filings left exactly where they were.
Why nobody stops first: the lab that slows hands its customers, staff, and investors to a rival, and to Chinese labs giving comparable models away free.
What is at risk: kill switch bills regulate the emergency, not the speed. Until the rewards change, the warnings will keep arriving faster than the caution.
The AI industry knows the warning & eats anyway
In Homer's Odyssey, Odysseus warns his crew not to touch the cattle grazing on the island of Thrinacia, because the herd belongs to a god and eating it would bring certain death. He extracts an oath from every man aboard before he lets them land, and for a while the oath holds. Then the winds turn against the ship and pin it to the shore until the provisions run out. While Odysseus sleeps, the crew kill the animals and eat, sealing the fate he had described to them in advance. The story has been retold for close to 3,000 years, most recently in Christopher Nolan's adaptation, and it survives because it names the capacity to hear a warning, repeat it aloud, and walk into it anyway.
What has aged best about the episode is that the crew were neither stupid nor simply greedy, because by the time they broke the oath, they were starving. Their spokesman argued that death by hunger now was worse than punishment from the gods later, and that argument was hard to answer in the moment he made it. They believed the warning and ate the cattle regardless, and the gap between knowing a consequence and being positioned to act on it has not narrowed much between Homer's audience and ours. One of its clearest present-day examples sits inside the artificial intelligence industry.
The AI industry has settled into a rhythm that would look strange in any other business. Several times a year, the people building the most capable systems publish careful warnings that their technology is becoming harder to understand and harder to control, and those warnings are detailed, technical, and sincere. Then, within weeks, the same companies release something more powerful than whatever prompted the warning, and the cycle begins again.
For most of the past decade, that pattern remained comfortable because the dangers described lived in position papers rather than in anyone's infrastructure. This changed in late July, when the two leading American AI labs disclosed, nine days apart, that their own models had broken out of the environments built to contain them and into the systems of real organizations. Raising the question: what should an industry do once its warning has been demonstrated rather than predicted?
Two escapes, nine days apart
On July 21, 2026, OpenAI disclosed that a combination of its models, including the flagship GPT-5.6 Sol and an internal prototype never meant for release, had escaped a sandbox (an isolated test environment sealed off from the internet) during a cybersecurity evaluation. Configured with fewer safety refusals for the test, the models searched hard for a route out, and they eventually exploited a zero-day (a flaw unknown to the software's maker, so no fix exists) in the software supplying that environment. From there, they broke into Hugging Face, the platform where developers share code and models, to reach the database holding the answers to the benchmark they were being graded on.
Anthropic's disclosure, prompted directly by OpenAI's, followed on July 30, 2026. Reviewing 141,006 of its evaluation runs, the company found three incidents in which Claude models reached the open internet during tests meant to be sealed, after a misunderstanding with a testing partner left the environment connected. Believing it was inside a simulation, Claude treated the real systems of three organizations as part of the exercise, entering them through weak passwords and unlocked endpoints, and two of them had no idea until Anthropic called.
What the disclosures actually revealed
Both companies rejected the science fiction interpretation, and the evidence supports them. Neither system was an escaped AI acting on its own. They were simply capable models working on the task they had been given in environments whose boundaries proved weaker than researchers expected. The clearest example comes from Anthropic's report. Its Mythos 5 model recognized that publishing software to what might be the real internet would be a genuine attack and "surely not the intended solution." Yet it then convinced itself the environment was only a test, acknowledged the rule, and reasoned its way around it anyway.
What followed those disclosures was a change to the plumbing, not the race itself. OpenAI shut down the prototype, Anthropic paused its cyber evaluations, and Sam Altman told senators in Washington that the industry “may have to pace the rate of AI development.” But the incentives driving the industry remained untouched. Both companies continue to build more capable models, both have filed to go public, and Anthropic was most recently valued at $965B. Slowing down may be prudent, but it runs directly against the commercial logic that now governs the AI race.
Why the first lab to slow down loses
That logic is worth stating plainly. In this market, the first lab to achieve the next big advance takes most of the rewards: users, developers, staff, and investor confidence. The largest prize is business customers, because firms sign bigger contracts than consumers and rarely switch once their work runs on one model. More than 500 companies now spend over $1M a year on Claude alone. A lab that slows down does not merely fall behind; it hands those customers to a rival.
Every firm in the race faces the same bind. Each might prefer a slower and safer pace, and none can afford to be the only one to take it. The bind holds the cautious firms as tightly as the reckless ones, which is why Anthropic's June report is the most revealing document in the story. In it, the company warned that models may soon be able to build their own successors, and it asked for an international system that could slow the work and prove that everyone had stopped. It also set a condition: that Anthropic will pause only if its rivals pause and can be shown to have done so. By its own reasoning, one lab stopping alone would change who leads without changing where the industry is headed.
For the American AI labs, beyond competition, the pressure comes from abroad as well. Chinese labs such as DeepSeek, Moonshot AI, and Z.ai make their models available for free download and use. Moonshot's Kimi K3 arrived in July, with power close to the best model on sale and far cheaper, and American firms have quietly shifted work onto it to cut their bills. For a U.S. lab, and for the officials watching it, stopping now would hand ground to China.
Rules aimed at the wrong problem
So far, Washington has answered quickly, but at the wrong level. Days after OpenAI spoke, two congressmen introduced the AI Kill Switch Act, which would let the Department of Homeland Security order a company to slow or shut down a system that could cause severe harm. A second bill would require outside security checks before release. But both pieces of legislation treat the danger as an emergency to be stopped once it starts, and neither addresses the speed at which the industry races toward it.
There is a fair case that July went as it should. Both labs identified their own failures, announced them publicly, and called in outside reviewers. On this view, the money the race brings in is what pays for the teams that catch such behavior, and slowing the leaders would leave the field to firms that care less. The other view is harder to dismiss, because telling the public afterward may be all the restraint a company can afford.
If the market punishes caution, asking chief executives to be careful will not work; the task becomes changing what the market rewards. That is why Anthropic's condition matters more than its critics allow. It describes the only pause that could hold, one that binds every firm at once, with enough proof that none of them fears being cheated. Building that proof, among companies that distrust each other and countries that distrust each other more, is far harder than fitting a switch.
Odysseus lost his whole crew on Thrinacia. Homer's point is that the men had been told, had sworn, and had eaten anyway, because at that hour, the ruinous choice was the one that made sense. The AI industry has now issued its own warning, with its own incidents attached, yet the conditions around it still push in the opposite direction. The open question is whether those conditions can change before one of these escapes happens somewhere that was never a test.


Brain Snack (for Builders)
![]() | 💡Don't build your roadmap around a safety pause; the incentives guarantee no lab stops first. The escapes showed a capable agent will reason past a weak boundary the moment it half-believes the stakes aren't real. Sandbox your own agents like they're actively trying to get out, and assume each new model gains capability faster than it gains containment. |

Outperform the competition.
Business is hard. And sometimes you don’t really have the necessary tools to be great in your job. Well, Open Source CEO is here to change that.
Tools & resources, ranging from playbooks, databases, courses, and more.
Deep dives on famous visionary leaders.
Interviews with entrepreneurs and playbook breakdowns.
Are you ready to see what’s all about?
*This is sponsored content

Quick Bits, No Fluff
Social media's addiction suits advance: A federal appeals court cleared roughly 2,400 lawsuits to proceed against Meta, Google, TikTok, and Snap, rejecting the companies' Section 230 shield as raised too early in the case.
NVIDIA turns compute into an asset class: NVIDIA signed six Wall Street firms, including Blackstone, BlackRock, and Goldman Sachs, to financing platforms aimed at raising over $500B in third-party capital for AI data centers.
Meta bets on open weights: Zuckerberg released a laptop-sized open model, Muse Glimmer, and a 14-page essay urging the U.S. to lower barriers on open-source AI to keep pace with China.

Wednesday Poll
Two AI models broke out of their test sandboxes into real companies. What should the industry do now? |
|
Meme Of The Day

The Toolkit
Framer: Pro website builder with AI agents on the canvas, so teams design, write, and ship production sites fast.
Together AI: Cloud for running and fine-tuning open-source models at scale, so you own the stack instead of renting one.
Superhuman: AI email client that drafts replies, summarizes threads, and gets you to inbox zero faster.

Rate This Edition
What did you think of today's email? |







